Connecting...
Effective date: 7/1/26 Last updated: 7/6/26
This Privacy Policy explains how Hillow.org handles information for the website hillow.org and all of its subdomains, sub‑sites, and self‑hosted applications (collectively, the "Service"). A single sign‑on account may give you access to multiple applications under this domain; this Policy applies to all of them unless a specific application shows its own additional notice.
This is a small, privately operated, hobby/personal service. It is run by an individual, is not a commercial enterprise, and is advertised to a limited number of users, yet it is open to anyone (primarily friends, family, and invited guests). We keep data collection to the minimum needed to operate.
Contact: [email protected]
What we do not collect: We do not collect biometric identifiers or biometric information (such as faceprints, fingerprints, or voiceprints); no application on the Service performs facial recognition or other biometric identification. We also do not collect government‑ID numbers or precise, always‑on background location.
We use strictly necessary cookies only. These are essential session and authentication cookies (for example, the single sign‑on session cookie and per‑application login cookies) that keep you logged in and secure your session. Some applications may set functional cookies to remember preferences (such as theme or language).
We do not use advertising cookies, cross‑site tracking, analytics profiling, or third‑party marketing trackers. Because our cookies are strictly necessary to provide a service you request, they are required for the Service to function; disabling them may prevent you from logging in.
Because we do not track you across other websites or services and do not serve behavioral advertising, there is nothing to opt out of. We therefore treat all users the same and do not change our behavior based on "Do Not Track" (DNT) or Global Privacy Control (GPC) browser signals — we simply do not perform the kind of tracking those signals are meant to stop.
We use the information above only to:
We do not use your content to build advertising profiles, and we do not perform automated decision‑making that produces legal effects about you.
You may choose to sign in using a third‑party account instead of, or in addition to, a local password. When you do, that provider shares a limited set of profile information with us — typically your name or username, email address, and profile picture — solely so we can create or match your account and log you in. We use this information only for authentication and account management, and we never receive the password you use with that provider. We currently support, or may support, the following sign‑in providers:
You can review or revoke our access at any time from within that provider's connected‑apps / permissions settings. Revoking access does not delete data already stored in your account here; to remove that, delete your account or contact us (see Section 8).
If you sign in with Google, Google shares your name, email address, and profile picture with us. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we:
You can review or revoke our access at any time at myaccount.google.com/permissions. Revoking access does not delete data already stored in your account here; to remove that, delete your account or contact us (see Section 8).
We do not sell your personal data, and we do not share it with third parties for their own marketing. We share information only in these limited cases:
Most of the Service is self‑hosted on our own hardware; your content generally is not handed to outside companies.
We protect the Service with measures including TLS/HTTPS encryption in transit, hashed password storage, access controls, single sign‑on, and admin‑gated access to non‑public areas. However, no method of transmission or storage is perfectly secure. We cannot guarantee absolute security, and you use the Service at your own risk (see also our disclaimer of data loss in Section 9 and in the Terms of Service).
Breach notification. If we become aware of a security breach that compromises your personal information, we will notify you and any regulators as required by applicable law, without undue delay, using the email address associated with your account.
Regardless of where you live, we offer all users the following:
To exercise any of these, email [email protected]. We will respond within a reasonable time. We will not discriminate against you for exercising these rights.
We do not sell your personal information, and we do not "share" it for cross‑context behavioral advertising, as those terms are defined under U.S. state privacy laws such as the California Consumer Privacy Act. We also do not use or disclose sensitive personal information for any purpose other than operating and securing the Service.
Sensitive and consumer health data: Some applications can hold health, fitness, location, or other sensitive information that may qualify as "consumer health data" under laws such as the Washington My Health My Data Act. We collect such data only when you voluntarily enter it into an application you choose to use, we use it only to provide that application to you, we do not sell or share it, and you may delete it at any time.
This is a hobby service provided on a best‑effort, "as‑is" basis. The Service, or any application within it, may be slowed, interrupted, modified, or permanently shut down at any time, with or without notice. We are not responsible for any loss, corruption, or deletion of your data. You are responsible for keeping your own independent backups of anything important to you. This is explained further in our Terms of Service.
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from anyone. Consistent with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under
delete it.
The Service is hosted on our own hardware in the United States. If you access it from outside the United States, you understand your information will be processed there.
We may update this Policy from time to time. When we do, we will change the "Last updated" date above and, for material changes, make reasonable efforts to notify account holders. Continued use of the Service after changes take effect means you accept the updated Policy.
The core Service is free. In the future we may offer optional paid features — for example a monthly subscription, additional cloud storage, or the ability to make a voluntary donation. If we do:
Donations are voluntary, non‑refundable gifts; they do not purchase any product or service or guarantee continued availability of the Service.
Questions, requests, or complaints about this Policy or your data:
hillow (operating as hillow.org) Email: [email protected] Website: https://hillow.org